Vulnerability Bulletins

SA-CORE-2011-001 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2011-001Project: Drupal coreVersion: 6.x, 7.xDate: 2011-May-25Security risk: CriticalExploitable from: RemoteVulnerability: Access bypass, Cross Site ScriptingDescriptionCVE: CVE-2011-2687Multiple vulnerabilities and weaknesses were discovered in Drupal.Reflected cross site scripting vulnerability in error handlerA reflected cross site scripting vulnerability was discovered in Drupals error handler. Drupal displays PHP errors in the messages area, and a specially

More info:

https://www.drupal.org/node/1168756